Hundreds of millions at risk from Chinese shopping app malware
The Chinese shopping app Pinduoduo, used by over 750 million people monthly, is accused of harboring malware that bypasses phone security to monitor user activity and is difficult to uninstall. Cybersecurity experts and former employees allege the app exploits Android vulnerabilities to spy on users and competitors, raising serious privacy concerns. The findings may impact its international sister app, Temu, which is rapidly growing in Western markets.
- ▪Pinduoduo is used by more than 750 million people each month and has been found to contain malware that can monitor other apps and read private messages.
- ▪Cybersecurity researchers and insiders say Pinduoduo exploited Android vulnerabilities to gain unauthorized access to user data and device functions.
- ▪Google removed Pinduoduo from the Play Store in March over malware concerns, and a Russian cybersecurity firm also reported finding potential malware in the app.
- ▪The app’s parent company, PDD, is listed on the Nasdaq and owns Temu, a fast-growing international shopping app not directly implicated in the allegations.
- ▪Pinduoduo has denied accusations of malicious behavior, and there is no evidence it has shared user data with the Chinese government.
- ▪US lawmakers remain concerned that Chinese companies could be compelled to cooperate with government data requests due to Beijing's legal authority over domestic firms.
Story provenance
Source · retrieval · rights · ranking — open for full record
inspect →
Story provenance
Attribution is not the same as permission. This drawer separates discovery metadata, excerpts, WeSearch-generated summaries, reuse status, and whether the publisher receives the visit. Nothing here claims a legal grant the publisher has not made.
Record
| Original publisher | CNN |
| Canonical URL | https://cnn.it/40OSomK |
| Publication time | 2023-04-02T16:05:29Z |
| Retrieval time | 2026-04-28T00:49:14.991Z |
| Last seen | 2026-04-28T00:49:14.991Z |
| Headline source | Publisher (no WeSearch rewrite) |
| Excerpt source | publisher body |
| Excerpt method | First ~120 words (~800 chars) of extracted publisher body, fair-use limited. |
| Summary | WeSearch · cerebras-chat (WeSearch summarizer) |
| Summary source text | contentText |
| Citation coverage | Summary is a WeSearch-generated derivative; primary citation is the original publisher URL. |
| Cluster | zbx_FTWu9cB- |
| Cluster logic | Grouped by semantic title/content similarity across sources within a rolling window. Same-publisher template collisions are excluded from coverage comparison. |
| Ranking reason | Story pages are not engagement-ranked. Hub feeds use recency, with optional source-diversified chronological ordering (cap consecutive stories per source). No personalized ranking. |
| Publisher visit | Yes — open original |
| Substitutes article? | No — link-out required for full text |
Rights status (four layers)
WeSearch handling by dimension
| Indexing | May the item be indexed (stored, ranked, made findable)? | Allowed |
| Snippet | May a short excerpt of the publisher's text be shown? | Allowed |
| AI summary | May WeSearch generate its own short summary of the article? | Limited |
| Retrieval / RAG | May the content be exposed for third-party retrieval-augmented generation? | Not asserted |
| Model training | May the content be used to train AI models? | Not asserted |
| Commercial reuse | May the content be reused commercially? | Not permitted |
Basis: Derived from the published RSS/Atom feed. Contact: [email protected]. Reviewed: 2026-07-24.
Opening excerpt (first ~120 words) tap to expand
window.CNN.contentModel.leadingMediaType = 'video'; window.CNN.contentModel.isVideoCollection = false; Facebook Tweet Email Link Threads Link Copied! It is one of China’s most popular shopping apps, selling clothing, groceries and just about everything else under the sun to more than 750 million users a month. But according to cybersecurity researchers, it can also bypass users’ cell phone security to monitor activities on other apps, check notifications, read private messages and change settings. And once installed, it’s tough to remove. While many apps collect vast troves of user data, sometimes without explicit consent, experts say e-commerce giant Pinduoduo has taken violations of privacy and data security to the next level.
…
Excerpt limited to ~120 words for fair-use compliance. The full article is at CNN.